diff --git a/docs/changelog-20260723-queue-pass.md b/docs/changelog-20260723-queue-pass.md index 482a55b..5d71527 100644 --- a/docs/changelog-20260723-queue-pass.md +++ b/docs/changelog-20260723-queue-pass.md @@ -250,3 +250,16 @@ remainder is now the Q2 path selection at Roosevelt design time. - REVERT: remove the amendment + section 0c; restore the CAUTION/tail passages + the two CURRENT-STATE passages. + +## Item 16 -- NetBox write-path obligations ROUTED to a findings doc + +- WHAT: the ledger retained block's directive ("route to a findings doc or + fix before the next NetBox write campaign") executed as ROUTE: new + `docs/netbox-write-path-findings.md` carries the still-open residue + (original #4 dumper blind spot + #5 duplicate-CIDR collapse UNFIXED; + hardened-fidelity re-run = C2 sub-task (i); campaign-time re-verify of the + 2026-07-14 fixes) with its trigger (any NetBox WRITE campaign; above all + the deferred apex merge-back). Archive re-read established that original + defects 1-3 + 6 were FIXED 2026-07-14 -- the routed doc records only what + is genuinely still open. Ledger retained block now points at the doc. +- REVERT: delete the doc; restore the ledger block text. diff --git a/docs/netbox-write-path-findings.md b/docs/netbox-write-path-findings.md new file mode 100644 index 0000000..78f2aba --- /dev/null +++ b/docs/netbox-write-path-findings.md @@ -0,0 +1,50 @@ +# NetBox write-path findings -- OPEN residue gating the deferred apex write-back + +**Status:** OPEN obligations, routed here 2026-07-23 from the session-ledger +retained block (which pointed only at the archived rotation). **Gates:** the +DEFERRED end-of-deployment write-back to the production apex +`netbox.baldurkeep.com` (DOCFIX-195: office1-netbox is the WORKING VR1 apex; +the production apex is READ-ONLY reference until then). These findings gate +THAT write campaign -- nothing current. + +**History:** six write-path defects found 2026-07-14 by adversarial review. +Defects 1-3 and 6 were FIXED the same day +(`docs/archive/changelogs/changelog-20260714-netbox-write-path-hardening.md`: +roles-importer preflight covers ARIN + ULA; prefixes-importer preflights +every role; fidelity check both-bounds + delta-scope-aware; test fake raises +on multi-match like real pynetbox). Full original text: +`docs/archive/session-ledger-rotated-20260719.md` ("OPEN -- NetBox +WRITE-PATH BUGS" section). + +## Open items (do ALL before the first production-apex write) + +1. **Same-dumper blind spot (original #4) -- NOT fixed.** + `sandbox-fidelity-check` compares two dumps produced by the SAME field + list, so any field the dumper omits is invisible on both sides by + construction (prefix `vrf`, `tenant`, `vlan`, `tags`, `custom_fields`; + site `tenant`/`group`/`facility`). Same structural shape as the + region-scope bug that once dropped 17 prefixes. Fix direction: widen the + dump field list, or add an independent field-coverage assertion. +2. **Duplicate-CIDR collapse (original #5) -- NOT fixed, latent.** + Prefix-keyed dicts in the seeder and fidelity check collapse duplicate + prefixes (NetBox permits them; the importer's own docstring anticipates + them vs `vr0-dc0`). A whole prefix object can vanish under a green check. + Latent only because no duplicates exist upstream today. The hardened fake + (#6 fix) makes this testable now. +3. **Re-run the fidelity check under the HARDENED version.** The sandbox's + "proven faithful" verdict (2026-07-14) was produced by the PRE-hardening + check that could false-green. Re-run `sandbox-fidelity-check.py` against + `office1-netbox` before trusting that verdict -- this re-run IS C2 + sub-task (i) per DOCFIX-195. +4. **Re-verify the 1-3 fixes at campaign time.** The fixes are two-plus + stages old; before the production write, re-run their harnesses and + re-read the preflight paths against the THEN-current NetBox/pynetbox + versions (hard rule: a fix verified in July is not evidence in a later + campaign). + +## Trigger + +The next NetBox WRITE campaign of any kind -- above all the deferred +`netbox.baldurkeep.com` merge-back at end-of-deployment. No write campaign +starts while items 1-2 are unfixed or 3-4 unrun. (Read-only NetBox use is +ungated.) diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 7442c12..e9ab527 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -76,10 +76,11 @@ bodies here -- sessions append BOUNDED summaries only (15-line cap). Retained compact blocks (still-live obligations without another home yet): -- **NetBox write-path bugs (2026-07-14 adversarial review; LOGGED, NOT - FIXED):** importer/write-guard defects recorded in the rotated body - ("OPEN -- NetBox WRITE-PATH BUGS" section) -- route to a findings doc or - fix before the next NetBox write campaign. +- **NetBox write-path bugs:** ROUTED 2026-07-23 to + `docs/netbox-write-path-findings.md` (the durable home; the rotated-body + section is history). Open residue: dumper blind spot + duplicate-CIDR + collapse unfixed, hardened fidelity re-run + fix re-verification owed -- + ALL gated on the next NetBox WRITE campaign, none current. - **Project-completion (after D-011 passes):** consolidate the 10 per-phase do-documents into a v1 deploy runbook; flip repo PRIVATE (SEC-004); revoke/rotate SEC-005/006/007; v2-deferred: GitBucket SSH, IPv6